Privacy policy
Last updated: 27 September 2026
This policy explains what RoamOver collects about you, why, and what you can do about it. It forms part of our terms of service. RoamOver is the data controller for everything described here. We do not sell your data, and we never use it for advertising.
You must be at least 18 to use RoamOver. We do not knowingly collect data from anyone younger; if you believe we have, contact us and we will delete it.
Account data
When you register, we store your email address, username and password, your password only as a hash, never in a form we could read back. During sign-up we ask for your outfit type and its dimensions so the map can show you places your vehicle fits; you can skip this and add or change it later from your profile. You can also optionally add a bio, an avatar photo, and a country and distance-unit preference.
We also record when your account was created, when you last signed in, and when you last changed your password, so we can spot unusual activity on your account.
Your email address is used to sign you in, to confirm you own the address, and for account security messages such as a verification code, a password reset code or a notice that your password changed. It is never used for marketing. Confirmation and reset codes are stored only as a hash, expire after a short time, and are deleted automatically once they have expired.
We rely on our agreement with you, the terms of service, as the legal basis for handling account data and your contributions, and on our legitimate interest in keeping the service secure for the security records described below.
Signing in and sessions
Each time you sign in we create a session record on our server so you can stay signed in on that device and so a session can be ended if it needs to be. The record holds a hashed session token, when it was issued, when it was last used and when it expires, up to 180 days after it was last renewed. It does not hold your device name, IP address or location. Signing out ends the session on that device; changing your password, or asking us to, ends all of them.
Device location
While you're using the map, the app reads your position to centre the map on you, draw the "my location" marker, set the starting point for a nearby search, and check whether you're close enough to a stopover to answer a question about it. That proximity check happens on your device.
Nearby stopover alerts are off unless you turn them on, and only available on Android. When enabled, the app keeps reading your location while it's in the background, Android shows a persistent notification while it does, asks our server for stopovers near you, and notifies you when you've stayed at one. The notifications are created on your device. Where you've been and how long you stayed are kept only on your device and never sent to us. Turning the setting off stops it.
If alerts are on, the app may also notice you left a stopover quickly and then stopped for the night somewhere else, and ask you the next morning whether you couldn't stay there. This is worked out entirely on your device; where you stopped and any directions you opened stay on your device too. Answering "just passing" sends nothing. This morning-after prompt has its own setting, separate from alerts themselves, so you can turn it off on its own.
Coordinates sent with a nearby search, including the searches alerts make, are used only to answer that one request and are not stored or attached to your account. The only coordinates we store against your account are pins you deliberately submit with a stopover.
Your contributions
Locations, photos, comments, rating answers and favourites you add are stored against your account. Submitted locations and comments are publicly visible, shown with your username unless your profile is set to private, in which case they show as anonymous. Rating answers are stored against your account but are only ever shown to others combined with everyone else's answers, never individually. Favourites and saved search filters are private to you.
Photos: location metadata and all other data your camera embeds in a photo are removed when you upload it. A photo you remove, or that a moderator removes, is kept for up to 30 days in case the removal was a mistake, and then deleted.
Moderators see who submitted each location, photo and comment so they can review it, and so they can act on a report. Reports you make about a comment are stored with your account, the reason you gave, and how the report was resolved; the person you reported is not told who reported them.
You can tell us about a stopover you visited — that the stay went well, or that you couldn't stay and why. We store the outcome, the reason you picked and any follow-up answer, the date of the visit and the part of the day you arrived, your outfit type and its dimensions at that moment, and when you sent it, against your account. Sending a report tells us you were at that stopover around that time — it's the one way a location visit reaches us, and only when you tap Send; answering "just passing" sends nothing. Your reports are shown to other users both **combined, as counts** — how many people recently stayed or couldn't, and why — and **individually**, in the place's activity feed: the outcome, the reason and follow-up you gave, an approximate date, and your vehicle type and rounded size — never your name, your profile, or your vehicle's exact size: a vehicle length or height is always rounded before anyone but you sees it. You can delete your own report at any time, and every report is deleted when you delete your account.
Feedback
Feedback you send us is stored exactly as you typed it, including anything you say about a bug or a problem with the app. Alongside the text, we store the app version and device platform you sent it from, the IP address it was sent from, and whether you were signed in when you sent it.
Security and abuse prevention
To stop abuse, our server briefly records your account or IP address against actions such as signing in, requesting a code or sending feedback. These records are deleted automatically once the limit window they apply to has passed.
If we ban an account for breaking the terms of service, we record when and why on the account, and we keep the email address on a block list so it cannot be used to register again. That block-list entry is kept even if the account is later deleted, for as long as the ban stands.
Our website and server logs
Our website, roamover.app, describes the app and publishes these policies. It sets no cookies, runs no scripts, shows no adverts, uses no analytics, and loads nothing from any other company. When a page is requested, our server records the time, the page and whether it was served — not your IP address or anything about your browser or device.
When the app talks to our server, the server records the time, the part of the service used and whether the request succeeded, so we can find and fix faults. It does not record your IP address, what you searched for or where you searched around. Our server uses your IP address only as described under "Feedback" and "Security and abuse prevention" above.
Third parties
MapTiler serves the map. Your device requests map images directly from it, so it receives your IP address and the area of the map you're viewing. If MapTiler is unavailable, map images come from OpenStreetMap on the same terms.
Geoapify answers place searches and address lookups. Our server sends it the search text or the coordinates being looked up, never your account details or your IP address. Results are cached on our server and are not linked to you.
Brevo delivers account emails on our behalf. It receives your email address and the content of those messages.
Each of these providers is in the United Kingdom, the European Economic Area or Switzerland, and handles data under the UK's data protection law or a regime the UK recognises as equivalent. We do not transfer your data anywhere else.
Data on your device
Map images and other app data are stored on your device so the app loads faster and works with a weak signal, including stopovers you have searched for, your favourites and your saved filters. This data is encrypted, tied to your signed-in account, removed automatically when you sign out, and kept within a size limit you control in App Settings, where you can also view and clear it.
The app also remembers, on your device only, which stopovers you've been within about 500 m of in the last 30 days, so it can offer "Couldn't stay here?" for them later. This is never sent to us; entries are removed after 30 days, and it's cleared when you sign out or clear app data in App Settings.
Retention and deletion
We keep your account data for as long as your account exists. You can delete your account yourself from your profile, or ask us to by email if you can't sign in. When you do:
- your account, email address, profile, avatar, photos, favourites, saved search filters, rating answers, comment reports, visit reports and session records are deleted;
- your comments and submitted locations stay, shown as anonymous, and can no longer be linked to you;
- feedback you sent stays, no longer linked to you;
- photos you added to someone else's location are deleted along with your account;
- if the account was banned, its email address stays on the block list.
Your rights
You can see and change most of what we hold about you from your profile and App Settings. Beyond that, you have the right to ask us for a copy of your data, to correct anything that is wrong, to delete it, to receive the data you gave us in a form you can take elsewhere, and to object to how we use it. To exercise any of these, email us from the address registered to your account; we will reply within 30 days. If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office at ico.org.uk.
Changes to this policy
If we change what we collect or how we use it, we will update this page and tell you in the app before the change takes effect.
For any privacy question, contact privacy@roamover.app.